How to Run a Ransomware Tabletop Exercise With Your Team

A ransomware tabletop exercise is one of the highest-value, lowest-cost things a small business can do before an incident happens. Here's how to run one, step by step.

A ransomware tabletop exercise is a structured conversation — not a live drill — where your team walks through how it would respond to an actual ransomware incident before one ever happens. It's one of the highest-value, lowest-cost things a small business can do for its security posture, and increasingly something cyber insurers expect to see documented.

Here's how to run one, even without a large IT team.

Step 1: Set the scenario. Pick something specific and realistic for your business — for example, "Monday morning, front-desk staff can't open patient files, and a ransom note appears on the shared drive." A vague scenario produces a vague exercise. Specificity forces real decisions.

Step 2: Get the right people in the room. This isn't just an IT exercise. Include whoever would actually need to make decisions during a real incident: practice leadership or ownership, whoever manages client or patient communication, your IT provider or internal IT lead, and anyone responsible for legal or compliance obligations (this matters a lot if PHI or financial data is involved).

Step 3: Walk the timeline hour by hour. Start at the moment of discovery and move forward in realistic increments. At each point, ask: Who gets notified first? Who has the authority to shut down affected systems? Do we know where our backups are and whether they're isolated from the affected network? Do we have cyber insurance, and do we know the claims-reporting deadline in our policy? Who talks to clients or patients, and what do they say before all the facts are known?

Step 4: Surface the uncomfortable gaps. The exercise is working if it makes people uneasy. Common gaps we see: nobody actually knows the cyber insurance policy's notification deadline (some require reporting within 24-48 hours); backup restoration has never been tested and nobody's sure how long it would take; there's no agreed-upon communication plan for clients, so the first draft of a client email gets written in a panic; and legal/breach-notification obligations (which vary by state and by whether PHI or financial data is involved) haven't been reviewed in advance.

Step 5: Write down what changed. The exercise itself doesn't fix anything — the follow-up does. Assign specific owners to specific gaps: "test backup restoration by [date]," "confirm cyber insurance reporting deadline and put it in the incident response document," "draft a template client-notification email in advance."

How often should you do this? Once a year at minimum, and after any significant change to your IT environment or vendor stack. The first exercise is always the most uncomfortable and the most valuable — it's where most of the real gaps get found.

If your business has never done one of these, that's normal — most SMBs haven't. It's also usually a half-day investment that prevents a much worse day later.

Ready to Stop Worrying About IT and Security?

Book a free 30-minute discovery call. No pressure, no jargon — just a straight conversation about where your business stands today.

Schedule a Discovery Call

Right Icon